Live data from Hacker News

Have I Been Pwned 2.0

troyhunt.com

211–220 of 323 posts

Re: Have I Been Pwned 2.0

#211

Earlier quoted context omitted.

That's fine for you personally, and it may sound all good from a logical, theoretical, or academic perspective, however I personally know of people who have lost their license due to multiple fines and "demerit points" (NZ) resulting in that consequence. The fines, and loss of license hurt them personally, professionally, and financially, but didn't change their behavior outside of the very short term. In NZ we have…

Then these people _obviously_ are not fit to drive a multi-ton killing machine at all and should have their license permanently revoked, when they had multiple chances for introspection.

I think whoever brought up the "fines as revenue" may have thought of Fenton, LA or the like: https://www.propublica.org/article/fenton-louisiana-brought-...

Re: Have I Been Pwned 2.0

#212
post #149

Earlier quoted context omitted.

If I drive carelessly and get a meaningful fine, I'll think twice next time, irrespective of who gets the money. I only care that I am fined. Unless the police starts to administer fines when they shouldn't, all is good, right? What happened in Belgium?

That's fine for you personally, and it may sound all good from a logical, theoretical, or academic perspective, however I personally know of people who have lost their license due to multiple fines and "demerit points" (NZ) resulting in that consequence. The fines, and loss of license hurt them personally, professionally, and financially, but didn't change their behavior outside of the very short term. In NZ we have…

The occasional fine I get (and the prospect of getting another) does affect my driving habits and attentiveness, and it's the same for people close to me. Can't talk for others, though I'd expect this to be the norm.

Re: Have I Been Pwned 2.0

#213
post #202

> It's likely a single-digit percentage of requests that are real humans being [blocked], and we need to look at ways to get that number down, but at least the fallback positions are improved now. The fallback suggestions mentioned in the article are "try clicking the box again" and "try reloading the page" I'm slowly starting to wonder if I should start sending snail mail to companies that block me, instead of resig…

Agreed, it seems like my (fixed) IP address is triggering Google and CF for some reason. I don't run any scrapers or so from home but do use NoScript, am I a bot for using NoScript? Perhaps.

Re: Have I Been Pwned 2.0

#214

Amazing that even within the last decade a site as large as LinkedIn could be storing unsalted passwords. How does anyone fail at this in the modern era?

Same company that requires you upload a biometric scan of your face paired with your passport for ""verification"" (despite not needing it on signup) if you want to enable MFA, btw ;-)

On a related note, I no longer have an active linkedin account.

Re: Have I Been Pwned 2.0

#216

Earlier quoted context omitted.

Probably impossible, but create a slush fund where companies that behave badly are forced to pay into so we can do things like fix roads and build housing.

We could also design some kind of electoral process for picking those in charge of defining the rules and creating yet more bodies to enforce it. Maybe this time we can come up with a better way to disincentivize corruption and bribery.

We could instead randomly select representatives instead of using popularity contests where the candidates need money for advertisements in order to get popular, or to just even let people know that they exist.[1]

https://en.wikipedia.org/wiki/Sortition

[1] But the real solution is getting rid of money.

Re: Have I Been Pwned 2.0

#217
post #103

Earlier quoted context omitted.

Ahh I see it on the footer of the website, a bit hidden! I'm not sure I really need it for personal use, more just a cool thing to see, so I'm a bit undecided on paying for the domain feature. I can see it being useful for a business though where each email is a different employee dealing with accounts everywhere.

You can pay for just one month at a time. I pay now and then and check in on my personal domain – like you, I use dozens of email addresses with a catchall.

Oh that's a good idea. I'm not sure 25 aliases would be enough though, that price jump is quite a bit.

Re: Have I Been Pwned 2.0

#218
post #182
post #171

Earlier quoted context omitted.

They (and the users) have a very real use case for that, just like a contacts app needs all of that. The problem is not keeping it safe.

No user ever had a real use case for seeing a button that says "invite X" that doesn't send an invite on the platform, but instead sends an email to X who doesn't have a Linkedin account. And if you decline, it asks you again. Two times using different wording.

You'll be surprised how many features "tech" people think nobody uses (Like a share button on a website), are actually very popular. That's likely the reason that feature still exists as everything is most likely A/B tested to death.

I was not only talking about that though, but also that they can build shadow profiles and recommend people to you that way.

Re: Have I Been Pwned 2.0

#219

Like many people I have a "main" email address, and I use per-company addresses for almost everything else. Now that the domain-searches require subscriptions this site has become much less useful. I just added my domain to the site again and I see "2,243 Total Breached Addresses", and "18 Addresses excluding Spam Lists", but I have no idea what they are. Attempting to click the links shows me I need to "upgrade" to…

Is your per-company addresses a derivation of your main email address?

If so, this is called “email tumbling” and services exist to strip the “per-company” part to expose your main email.

Re: Have I Been Pwned 2.0

#220

Like many people I have a "main" email address, and I use per-company addresses for almost everything else. Now that the domain-searches require subscriptions this site has become much less useful. I just added my domain to the site again and I see "2,243 Total Breached Addresses", and "18 Addresses excluding Spam Lists", but I have no idea what they are. Attempting to click the links shows me I need to "upgrade" to…

I used to just add the +something in my email but now I try and remain diligent to create a masked email. When I first started, I foolishly did it with my domain name but have since moved to creating it with @fastmail.com.
Post reply on HN